CVE-2015-3257: XSS
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
Other sources
Potential XSS and Open Redirect vectors in zend-diactoros
Zend/Diactoros/Uri::filterPath in zend-diactoros before 1.0.4 does not properly sanitize path input, which allows remote attackers to perform cross-site scripting (XSS) or open redirect attacks.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2015-3257?
CVE-2015-3257 can lead to cross-site scripting (XSS) attacks and open redirect vulnerabilities due to improper sanitization of path input.
How do I fix CVE-2015-3257?
To fix CVE-2015-3257, update the zend-diactoros package to version 1.0.4 or later.
Which versions of zend-diactoros are affected by CVE-2015-3257?
CVE-2015-3257 affects all versions of zend-diactoros from 1.0.0 up to and including 1.0.3.
Is CVE-2015-3257 a critical vulnerability?
CVE-2015-3257 is considered a high severity vulnerability due to its potential exploitation vectors.
How can I verify if my application is vulnerable to CVE-2015-3257?
You can verify vulnerability by checking if your application uses zend-diactoros versions before 1.0.4.